OpenBSD errata
marc.info
marc.info
It irks me that OpenSSL would keep a vulnerability from the LibreSSL team since August. I hope people using OpenSSL will begin to switch over now. LibreSSL has shown that it is no going away, and that it approaches security in a far better way.
Not even sure what the right reaction to that is. On one hand, good for you for skipping an insecure patch but on the other hand, only a bad feeling? You didn't realize it's a security hole?
You also sometimes get a bad feeling without being able to say exactly what's wrong - it just feels/looks bad. That's when you should seek additional input from your peers.
Rejecting code based on 'smells wrong' can be sane. The submitter should then explain better why the code is sane.
CVE-2015-13XX should be CVE-2015-31XX.